GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,100 advisories
Filter by severity
Code injection via unsafe YAML loading
High
CVE-2021-43811
was published
for
sockeye
(pip)
Dec 9, 2021
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this...
High
Unreviewed
CVE-2021-37097
was published
Dec 9, 2021
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an...
Critical
Unreviewed
CVE-2021-44529
was published
Dec 9, 2021
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote,...
Moderate
Unreviewed
CVE-2021-29113
was published
Dec 8, 2021
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x...
High
Unreviewed
CVE-2021-35413
was published
Dec 4, 2021
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the...
High
Unreviewed
CVE-2021-3725
was published
Dec 1, 2021
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute...
Moderate
Unreviewed
CVE-2021-38967
was published
Dec 1, 2021
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Moderate
Unreviewed
CVE-2021-43221
was published
Nov 25, 2021
Code injection in spring-cloud-netflix-hystrix-dashboard
High
CVE-2021-22053
was published
for
org.springframework.cloud:spring-cloud-netflix-hystrix-dashboard
(Maven)
Nov 23, 2021
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in...
Moderate
Unreviewed
CVE-2021-33493
was published
Nov 23, 2021
The affected controllers do not properly sanitize the input containing code syntax. As a result,...
High
Unreviewed
CVE-2021-38448
was published
Nov 23, 2021
Critical vulnerability found in cron-utils
Critical
CVE-2021-41269
was published
for
com.cronutils:cron-utils
(Maven)
Nov 15, 2021
Template injection in thymeleaf-spring5
Critical
CVE-2021-43466
was published
for
org.thymeleaf:thymeleaf-spring5
(Maven)
Nov 10, 2021
Code injection in `saved_model_cli`
Moderate
CVE-2021-41228
was published
for
tensorflow
(pip)
Nov 10, 2021
Code Injection in SLO Generator
Moderate
CVE-2021-22557
was published
for
slo-generator
(pip)
Oct 5, 2021
Cobbler before 3.3.0 allows log poisoning
High
CVE-2021-40323
was published
for
cobbler
(pip)
Oct 5, 2021
Improper Input Validation and Command Injection in Ansible
High
CVE-2021-3583
was published
for
ansible
(pip)
Sep 23, 2021
Improper Control of Generation of Code ('Code Injection') in @asyncapi/modelina
Critical
CVE-2023-23619
was published
for
@asyncapi/modelina
(npm)
Sep 21, 2021
Insertion of Sensitive Information into Externally-Accessible File or Directory and Exposure of Sensitive Information to an Unauthorized Actor in hbs
Moderate
CVE-2021-32822
was published
for
hbs
(npm)
Sep 2, 2021
Code injection in codiad
Critical
CVE-2019-19208
was published
for
codiad/codiad
(Composer)
Sep 1, 2021
remote code execution via git repo provider
Critical
CVE-2021-39159
was published
for
binderhub
(pip)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API